Anti-Malware Engine Selection via Detection Intelligence

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing anti-malware solutions face challenges in effectively detecting and combating constantly evolving malware, as they rely on signature-based detection methods that require frequent updates and can lead to performance issues when using multiple engines simultaneously, resulting in inconsistent protection across different malware strains.

Innovation Solution

A method is introduced to select a subset of anti-malware engines based on current detection intelligence and operational effectiveness, using information from various sources to rank engines and activate only the most effective ones, thereby balancing detection capabilities and performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple anti-malware engines are used simultaneously, then malware detection capability is improved, but system performance deteriorates

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system dynamically selects and activates anti-malware engines based on real-time detection intelligence and operational effectiveness data. Instead of running all engines simultaneously, the system adapts its configuration by activating only the most effective engines for current malware threats, thereby maintaining high detection capability while optimizing system performance

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes operational parameters by adjusting which anti-malware engines are active based on detected malware characteristics and engine effectiveness metrics. This parameter adjustment allows the system to optimize the balance between detection capability and performance by selecting the appropriate subset of engines for each operational context

Inventive Principle:
Principle #35Parameter changes

2Reliability

If all anti-malware engines are activated, then detection coverage is improved, but device complexity increases

Engineering Contradiction:
Improvedetection coverageVSAvoidengine management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts and activates only the necessary subset of anti-malware engines based on current detection needs and effectiveness data. By taking out only the relevant engines rather than activating all available engines, the system maintains comprehensive detection coverage for prevalent threats while reducing the complexity of managing multiple simultaneous engine operations

Inventive Principle:
Principle #2Taking out (Extraction)

3Measurement precision

If signature-based detection is used, then detection accuracy is improved, but adaptability to new malware deteriorates

Engineering Contradiction:
Improvedetection accuracyVSAvoidresponse to evolving malware
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by maintaining multiple anti-malware engines with different detection capabilities and methodologies. This preparation allows the system to quickly switch between engines or activate specific engines that are effective against new or evolving malware strains, improving adaptability while maintaining detection accuracy through the availability of multiple specialized engines

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes detection parameters by selecting different anti-malware engines based on the characteristics of detected malware. This parameter change allows the system to adapt its detection approach - using signature-based engines for known threats and alternative detection methods for new or evolving malware, thereby maintaining both accuracy and adaptability

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9245124B2Application selection using current detection intelligence
Publication Date: 2016.01.26 MICROSOFT TECHNOLOGY LICENSING LLC
  • US9245124B2 patent drawing
  • US9245124B2 patent drawing
  • US9245124B2 patent drawing

AI summary

Selecting one or more applications from the plurality of similar or near redundant applications to activate. A method includes retrieving information about current characteristics of one or more applications. The method further includes retrieving information about a current computing operational landscape. Based on the information about current characteristics of one or more applications and the information about a current computing operational landscape, the method further includes creating a ranking of applications. The rankings are made available to a system with a plurality of applications with similar or near redundant functionality. At the system, one or more of the applications in the plurality of applications are selected to activate based on the ranking of applications.